CVE-2026-54874
- EPSS 0.52%
- Veröffentlicht 25.08.2026 13:19:24
- Zuletzt bearbeitet 11.09.2026 21:16:28
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL ...
CVE-2026-14457
- EPSS 0.98%
- Veröffentlicht 25.08.2026 13:17:49
- Zuletzt bearbeitet 11.09.2026 21:14:35
Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw publi...
CVE-2026-18798
- EPSS 1.48%
- Veröffentlicht 25.08.2026 13:17:49
- Zuletzt bearbeitet 23.09.2026 16:07:09
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leadin...
CVE-2026-14456
- EPSS 0.47%
- Veröffentlicht 13.08.2026 13:55:52
- Zuletzt bearbeitet 28.08.2026 19:46:29
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer ...
CVE-2026-54876
- EPSS 0.26%
- Veröffentlicht 05.08.2026 13:59:36
- Zuletzt bearbeitet 28.08.2026 19:46:29
Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker-tunable amou...
CVE-2026-69247
- EPSS 0.18%
- Veröffentlicht 03.08.2026 21:16:32
- Zuletzt bearbeitet 10.09.2026 20:36:14
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encry...
CVE-2026-45446
- EPSS 0.37%
- Veröffentlicht 09.06.2026 16:03:32
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can for...
CVE-2026-45447
- EPSS 5.24%
- Veröffentlicht 09.06.2026 16:03:32
- Zuletzt bearbeitet 18.09.2026 13:18:26
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execu...
CVE-2026-45445
- EPSS 0.6%
- Veröffentlicht 09.06.2026 16:03:31
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key us...
CVE-2026-42771
- EPSS 0.22%
- Veröffentlicht 09.06.2026 16:03:30
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Impact summary: This out of bounds read will not direc...